Observed Signal · May 20, 2026 · Data Breach · Source: techcrunch · Impact: 4/5 · Sentiment: Negative

GitHub Hack: Data Stolen from ~3,800 Internal Repos

Executive Signal Summary

GitHub, owned by Microsoft, confirmed a security breach in which attackers stole data from approximately 3,800 of the company’s internal code repositories. The company said it detected and contained a compromise of an employee device that involved a poisoned Visual Studio Code (VS Code) extension. GitHub reported no evidence so far that customer information stored outside of its internal repositories was impacted, and its investigation remains ongoing. A hacking group called TeamPCP has claimed responsibility and is reportedly selling the stolen data on a cybercrime forum. The incident follows a pattern of supply‑chain attacks against developer tools and extensions, with prior related breaches affecting Trivy, the European Commission, Tanstack, and resulting targeting of other major tech organisations.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

GitHub is a central developer platform; a breach involving a poisoned code‑editor extension and thousands of internal repositories raises supply‑chain and credential exposure risks that can cascade across software projects and cloud services.

SIGNAL RADAR

Track Microsoft Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • GitHub confirmed attackers stole data from around 3,800 internal code repositories.
  • The compromise involved an employee device and a poisoned Visual Studio Code extension.
  • GitHub said it has no evidence of impact to customer information stored outside of GitHub’s internal repositories; investigation is ongoing.
  • A hacking group named TeamPCP claimed credit and is reported to be selling the stolen data on a cybercrime forum.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: techcrunch•Published: May 20, 2026
Original Coverage Title: “GitHub says hackers stole data from thousands of internal repositories”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Platform Security / Data BreachMay 20, 2026

Team‑PCP steals 3,800 internal GitHub repositories

The hacker group Team‑PCP accessed approximately 3,800 internal GitHub repositories between May 18 and May 19, 2026, and is attempting to sell the stolen data. GitHub confirmed the incident on X and said no customer data was affected. According to GitHub, attackers used a compromised employee device that had a malicious Visual Studio Code extension installed; the impacted endpoint was isolated and incident response measures were taken. Team‑PCP, previously linked to a March 2026 supply‑chain attack and said to collaborate with the Ransomware‑as‑a‑Service operator Vect, is offering the GitHub data for sale and reportedly coordinated with the LAPSUS$ group in later negotiations.

Read assessment
Supply Chain AttackJun 8, 2026

Microsoft GitHub Repos Injected with Password-Stealing Malware

Microsoft disabled access to dozens of its open-source GitHub repositories after security researchers flagged malware injected into project code that steals passwords and credentials when developers open the compromised tools in AI coding apps. Affected projects include Azure-related tools and developer integrations for AI coding environments such as Claude Code, Google’s Gemini CLI and VS Code. Security firms Cloudsmith and OpenSourceMalware were among the first to report the incident. At least 70 Microsoft-owned repositories were marked disabled on GitHub. The incident appears related to a recent mid-May compromise of Microsoft’s Durable Task project and has been described by researchers as a potential re-compromise or follow-on breach.

Read assessment
SecurityMay 14, 2026

OpenAI: Hackers Stole Data After Supply-Chain Attack

OpenAI confirmed on May 14, 2026 that two employees’ devices were impacted by a recent supply‑chain attack that abused a compromised open‑source project (TanStack). After investigation, OpenAI said attackers accessed a limited subset of internal source code repositories and stole “only limited credential material,” but found no evidence that user data, production systems or intellectual property were compromised. TanStack disclosed that attackers published 84 malicious npm package versions during a six‑minute window; the malicious packages were designed to steal credentials and self‑propagate. As a precaution, OpenAI is rotating digital certificates used to sign products, an action that will require macOS users to update the app. The incident is part of a broader wave of supply‑chain compromises targeting developer tooling.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.